OTSecurity

Black Kite: Manufacturing ransomware surged in 2026, spreading beyond the US, with 1,183 victims through July


New data from Black Kite’s 2026 Manufacturing & Distribution Ransomware Report identified that manufacturers continue to bear a disproportionate share of ransomware attacks, accounting for 22% of the 7,551 publicly disclosed ransomware victims across all industries. Ransomware attacks against manufacturers have more than doubled since 2023, with incidents increasing 39.7% year over year during the first seven months of 2026 to 1,183 victims, already surpassing the full-year total recorded in 2024. 

The 44-page report also points to a shift in ransomware activity toward mid-market companies and manufacturers outside the U.S. Companies generating $10 million to $100 million in annual revenue represented 70.2% of manufacturing victims, while the median victim generated $42.9 million. European manufacturing victims increased by 85.4%, reducing the U.S. share of global manufacturing ransomware victims from 52.3% to 34.8%. Germany alone recorded an increase of more than 83% in manufacturing victims during the first seven months of 2026 compared with the same period in 2025.

“What makes manufacturing and distribution so attractive to ransomware operators is the immediate operational impact,” Ferhat Dikbiyik, chief research and intelligence officer (CRIO) at Black Kite, said in a Thursday media statement. “One successful attack can stop production lines and disrupt delivery commitments, and every hour of downtime strengthens the attacker’s negotiating position. But attackers don’t operate blindly. Their reconnaissance relies on externally visible signals, from unpatched systems and exploitable services to leaked credentials and misconfigured defenses. Black Kite analyzes that same external attack surface, giving organizations a view of what adversaries can already see and where they may be most vulnerable.”

Manufacturing ransomware attacks reached a critical inflection point in 2026, with 1,183 victims in the first seven months alone, exceeding the entire 2024 total and marking 39.7% year-over-year growth. Nearly half of these incidents came from threat groups absent in 2023 and 2024, demonstrating how the attacker ecosystem rebuilt itself over two years. A single new entrant, The Gentlemen, accounts for 12.0% of the year’s incidents independently.

Mid-market remains the primary target, with 70.2% of victims operating in the $10 million to $100 million revenue band, where the median victim generates $42.9 million. Manufacturing ransomware is globalizing: European victims grew substantially enough to reduce the US share from 52.3% to 34.8%, driven largely by growth in Germany, where manufacturing comprises 19.9% of the national economy, while the U.S. victim count remained stagnant, barely declining from 443 to 412 cases.

Black Kite’s 2026 Manufacturing & Distribution Ransomware Report found that ransomware activity against manufacturers has continued to rise, with 1,020 incidents recorded in the first half of 2026, the highest half-year total in the dataset. The first-half figure was up 34.2% from 760 incidents in the first half of 2025. The research also recorded 1,183 manufacturing incidents from Jan. 1 through July 29, compared with 847 during the same period in 2025, a 39.7% increase.

Manufacturing ransomware activity has increased every year since 2022, according to the report. Black Kite tracked 540 incidents in 2022, 926 in 2023, 1,071 in 2024, and 1,600 in 2025. Manufacturing accounted for 1,660 of the 7,551 publicly disclosed ransomware victims identified across all industries in Black Kite’s broader 2026 Ransomware Report, representing 22% of all disclosures and marking the fifth consecutive year that manufacturing held the top position.

Black Kite reported that the climb in manufacturing victims over the years is not the work of any single corner of the industry. “Machinery Manufacturing leads the full period with 701 victims (15.2% of subsector-classified victims), followed by Fabricated Metal Products with 515 (11.2%), Transportation Equipment with 425 (9.2%), Chemical Manufacturing with 423 (9.2%), Computer and Electronic Products with 407 (8.8%), and Food Manufacturing with 361 (7.8%). Together, the top five account for just over half of all classified victims.”

It added that at the finer level of detail, industrial machinery and general purpose machinery makers top the list, with pharmaceutical manufacturers close behind at 194 victims. These are the subsectors where a stopped line converts most directly into missed shipments and contractual penalties, and that conversion is precisely the pressure ransomware operators monetize. The trajectories beneath the totals differ, and they suggest a wave that rotates rather than parks. Fabricated Metal Products absorbed the earliest and steepest climb, more than tripling from 64 victims in 2023 to 210 in 2025, then cooled to 16.4% same-period growth in 2026 while everything around it accelerated.

“Seven of the eight largest subsectors grew by more than 55% in the 2026 same-period comparison, led by Electrical Equipment (up 96.6%), Computer and Electronics (up 90.5%), and Chemicals (up 74.2%),” according to the report. “Even Transportation Equipment, the flattest series through 2025, joined the acceleration at 57.9%.”

The shift toward mid-sized victims runs through nearly every subsector, with one exception. 

“Comparing 2023-2024 with 2025-2026, the share of victims with revenues above $1 billion fell from 9.5% to 5.2% across the dataset, and it fell in seven of the eight largest subsectors,” Black Kite identified. “Transportation Equipment moved the other way. Its billion-dollar victim share rose from 13.2% to 15.7%, making it the one subsector where enterprise targeting intensified while the rest of the industry’s attackers moved downmarket. The reason matters for what follows. This is the subsector of automotive and aerospace supply chains, where the largest companies sit at the center of the deepest supplier networks.”

Black Kite mentioned that across the full 2023-2026 period, four groups dominate the manufacturing victim count. Qilin (455 incidents), Akira (385), LockBit 3.0 (355), and Play (335) are together responsible for 32% of incidents in the dataset. That full-period ranking, however, describes a hierarchy that no longer exists. 

“In the first seven months of 2026, the leaderboard reads Qilin (178), The Gentlemen (142), Akira (96), DragonForce (70), and INC Ransom (65), and one of those five, The Gentlemen, did not exist in the dataset before September 2025, while DragonForce and INC Ransom entered it with single-digit counts in 2023,” according to the report. “The decline side of that leaderboard is just as sharp. Play ranks fourth across the full period with 335 incidents and recorded only 39 in 2026. Medusa fell to 4. SafePay, the group concentrating on German targets, posted 29, and Clop registered 9, which is what a mass exploitation specialist looks like between campaigns.”

Qilin accounted for eight manufacturing incidents in 2023, 245 in 2025, and 178 in the first seven months of 2026, making it the most active group in the sector across each recent period. Barracuda’s analysis of Qilin’s 2025 activity found that manufacturing was its most attacked sector, accounting for roughly 23% of the group’s leak site listings. The Gentlemen went from its first appearance in September 2025 to second place in 2026.

Behind them, DragonForce grew from six incidents in 2023 to 70 in the first seven months of 2026, while INC Ransom increased from nine incidents to 65 over the same period.

The Black Kite report noted that ransomware attacks begin long before the encryption starts. Attackers start with reconnaissance, mining externally visible data, unpatched systems, exploitable services, leaked credentials, and misconfigured defenses, which form the raw material for targeting. Black Kite’s data collection mirrors this adversary vantage point, scanning the same signals and susceptibility markers that threat actors exploit. It maps the visible attack surface across the 1,000 largest manufacturers and 2,289 monitored distribution companies, revealing what the sector’s adversaries can already see, based on scan data collected through August 2026.

Across the EU, U.K., and North America, lawmakers are converting third-party cyber risk management from best practice into enforceable legal requirement. The EU’s NIS2 Directive explicitly names manufacturing subsectors—machinery, motor vehicles, computers and electronics, electrical equipment, and medical devices—alongside postal and courier services. 

Regulated companies must now manage supply chain security as a mandatory obligation, with fines reaching €10 million or 2% of global turnover. Germany implemented its NIS2 transposition in December 2025 with no transition period, while Italy’s cybersecurity agency requires regulated firms to identify and register suppliers critical to their operations. Notably, Germany and Italy rank among the countries with the highest concentrations of manufacturing ransomware victims in 2026.

The U.K.’s Cyber Security and Resilience Bill was introduced in November 2025, weeks after the JLR shutdown, and is aimed squarely at the supply chain. Roughly 1,000 managed service providers come under direct regulation for the first time, while regulators gain the power to designate critical suppliers, which must then meet the same security and reporting standards as the companies they serve.

Under the bill, ransomware incidents become reportable within 24 hours, with penalties of up to £17 million or 4% of global turnover. The gap is instructive. Manufacturers such as JLR themselves remain outside the bill’s direct scope, a point acknowledged in the parliamentary debate. The incident that accelerated the law is the kind of incident the law does not cover.

Black Kite mentioned that the U.S. regulates American manufacturing through procurement rather than legislation. The Cybersecurity Maturity Model Certification (CMMC) program, which began phasing into defense contracts in November 2025, makes third-party certification a condition of doing business with the Department of Defense and flows down through subcontractor tiers. This effectively regulates a large share of American manufacturing through procurement requirements.

Medical device manufacturers must now document the software components inside their products for the FDA. Meanwhile, the pending CIRCIA rule names critical manufacturing and transportation systems among the sectors that will be required to submit federal incident reports within 72 hours.

Black Kite identified that the Clop group’s 2025–2026 campaign against Cleo, a managed file transfer platform used by thousands of companies, exploited two critical vulnerabilities identified in late 2024 and produced nearly 400 disclosed victims. Within eight weeks, the attack surface included 128 manufacturing and 52 distribution victims, a dramatic escalation from the group’s 11 manufacturing incidents across all of 2024. 

The Oracle E-Business Suite campaign followed the same pattern: one compromised platform, thousands of organizations exposed at once. A manufacturer cannot patch vulnerabilities in software it does not own; for corporate buyers, a vendor’s exposed system becomes part of their own ransomware attack surface regardless of whether it appears in asset inventories. 

Black Kite detailed that manufacturing does not sit at the edge of supply chain risk; it sits in the center, where a leak-site disclosure immediately surfaces inside vendor lists of every company that depends on the victim’s output. 

The August 2025 Jaguar Land Rover cyberattack illustrates the scale: production stopped for five weeks at three UK plants, generating an estimated £1.9 billion financial impact across more than 5,000 affected organizations, primarily small and medium-sized suppliers. Evtec Group, a Coventry-based supplier, placed 900 employees on short-time work at reduced pay and estimated its own loss at £13 million; weekly disruption costs approached £50 million. Mid-market manufacturers, with a median revenue of $42.9 million, shoulder the highest attack volume precisely because they form the sourcing tier for larger enterprises.

As of August 2026, 74.8% of the largest manufacturers carry critical vulnerabilities rated CVSS 8 or above, while 61.4% carry CVSS 9 or higher. Beyond patch gaps, 69.1% show stealer log findings, 54.2% host at least one known exploited vulnerability, and 47.6% have phishing URLs targeting their domains. Infrastructure misconfiguration compounds the risk: 35.6% show misconfigured DMARC records, 34.3% register active botnet infections, and 29.8% have recorded data breaches. These findings reflect the externally visible attack surface that ransomware operators exploit during reconnaissance.

In conclusion, Black Kite observed that manufacturing companies face a multiplied exposure problem: they inherit risk from vendors above them and transmit disruption to customers below them, while the attacker ecosystem rebuilds itself faster than any annual assessment can track. Regulatory frameworks across the EU, UK, and US have transformed supplier security from optional best practice into an enforceable obligation, but most internal security programs lack visibility outside their own perimeters. Managing that exposure requires a vantage point designed specifically to see third-party risk as it operates in real time.

Effective supplier risk management pivots on six operational capabilities. Risk teams must prioritize vendors using observable ransomware susceptibility scores rather than treating all suppliers as uniformly risky, and measure them continuously against the technical conditions attackers currently exploit rather than betting on named adversary persistence. Equally critical: mapping Nth-party dependencies to surface concentration risk, acting on exposed vendors within the narrow window after disclosure but before campaigns scale, and replacing annual reviews with continuous monitoring that catches supplier posture shifts as they happen—a requirement embedded in NIS2 Article 21’s continuous obligation.

The final capability translates technical posture into operational impact. Cybersecurity scores hold no traction with boards and regulators; downtime does. Quantifying supplier risk through financial impact modelling, covering expected days of production loss and annualized business interruption costs, speaks the language manufacturers already use and regulators increasingly demand, converting abstract cyber metrics into the business continuity terms that drive investment and response.



Source link